Backdoor

How to remove “Backdoor:Win32/Darkshell.A”?

Malware Removal

The Backdoor:Win32/Darkshell.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Darkshell.A virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to stop active services
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor:Win32/Darkshell.A?


File Info:

crc32: CC214FF9
md5: c8713f816c814b6929450c4fdf55115e
name: C8713F816C814B6929450C4FDF55115E.mlw
sha1: 174d675517886c40379dfbdd8e20d67087800de7
sha256: 98fe62e82556a3fe2ec61e160b9afc0ef84bac8963e2b91d9974c697e95a4c2b
sha512: 9bf893511345e1689475ba1003943240cba2c8646e72847e752a24e8e185746cb27d631953a8b31e4a0ed3720ea522736bea4de135b80e45700a7cd0c1eb1cd5
ssdeep: 3072:IZGYLZW/0zu8NK0XbYlw9O6Jf7m85XxgP0F9o68ej:oZLzuX0rz06JfakNie
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Backdoor:Win32/Darkshell.A also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner.1826
CynetMalicious (score: 100)
ALYacGen:Variant.Kazy.35387
CylanceUnsafe
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaRansom:Win32/Gimemo.07a9e538
Cybereasonmalicious.16c814
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/AutoRun.IM
APEXMalicious
AvastWin32:Rootkit-gen [Rtk]
BitDefenderGen:Variant.Kazy.35387
NANO-AntivirusTrojan.Win32.Delf.djhdg
ViRobotTrojan.Win32.A.Gimemo.161280.B[UPX]
MicroWorld-eScanGen:Variant.Kazy.35387
TencentWin32.Trojan.Gimemo.Szbd
Ad-AwareGen:Variant.Kazy.35387
SophosMal/Generic-R + Mal/EncPk-AAI
ComodoTrojWare.Win32.Trojan.XPACK.Gen@2ho5ur
BitDefenderThetaGen:NN.ZexaF.34688.jmGfaOMt6Yfi
ZillyaTrojan.Delf.Win32.36348
EmsisoftGen:Variant.Kazy.35387 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor/Delf.vqf
WebrootTrojan.Dropper.Gen
AviraTR/Crypt.ULPM.Gen
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Malware.Heur_Generic.B.(kcloud)
MicrosoftBackdoor:Win32/Darkshell.A
AegisLabTrojan.Win32.Delf.l!c
GDataGen:Variant.Kazy.35387
AhnLab-V3Trojan/Win32.Menti.R14485
Acronissuspicious
McAfeeGeneric.emx
MAXmalware (ai score=100)
VBA32BScope.Trojan.Winlock.2981
PandaGeneric Malware
TrendMicro-HouseCallWORM_GAMANIA.DK
RisingRansom.Gimemo!8.306 (CLOUD)
YandexTrojan.Kryptik!BSZdrq9jIYI
IkarusTrojan-Ransom.Gimemo
FortinetW32/Gimemo.CEH!tr
AVGWin32:Rootkit-gen [Rtk]
Paloaltogeneric.ml

How to remove Backdoor:Win32/Darkshell.A?

Backdoor:Win32/Darkshell.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment